CVE-2024-36342 describes an improper input validation vulnerability in an unspecified GPU driver, potentially leading to arbitrary code execution via a heap overflow. With a CVSS score of 8.8 (HIGH), it presents a significant risk, allowing a local attacker with low privileges to achieve high impact on confidentiality, integrity, and availability. While the vulnerability is not currently listed on the KEV catalog and lacks public exploit code (Metasploit, Nuclei, ExploitDB), its FAUCET Risk Score of 83/100 indicates a high potential for exploitation. There is currently no community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
| AMD | AMD Athlon™ 3000 Series Desktop Processors With Radeon™ Graphics | Range not provided by sourceCNA affecteddefault affected | |
| AMD | AMD Athlon™ 3000 Series Mobile Processors With Radeon™ Graphics | Range not provided by sourceCNA affecteddefault affected | |
| AMD | AMD Instinct™ MI210 | Range not provided by sourceCNA affecteddefault affected | |
| AMD | AMD Instinct™ MI250 | Range not provided by sourceCNA affecteddefault affected | |
| AMD | AMD Instinct™ MI300A | Range not provided by sourceCNA affecteddefault affected |
CVSS version used by this source: 3.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.2 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.